Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A company wants to prevent users from sharing files containing personally identifiable information (PII) with external recipients. They also need to notify users if they attempt to share such files. Which Microsoft Purview solution should be configured?

⚠ Common exam trap

Many candidates confuse Sensitivity Labels with DLP, but Sensitivity Labels only classify and protect data without enforcing sharing restrictions or user notifications, whereas DLP is the solution that actively monitors and blocks the external sharing of sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Data Loss Prevention

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect, prevent, and notify users about the sharing of sensitive data, such as personally identifiable information (PII), with external recipients. DLP policies can be configured to automatically block the sharing of files containing PII and display a policy tip notification to the user when they attempt to share such content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Purview Sensitivity Labels

    Why it's wrong here

    Sensitivity labels classify and encrypt content, but they neither detect PII patterns automatically nor block sharing with a user notification. They suit persistent protection travelling with a file. Data loss prevention matches PII and blocks external sharing with policy tips.

  • ✗

    Microsoft Purview Communication Compliance

    Why it's wrong here

    Communication Compliance scans chat, email, and Teams messages for policy violations, but it does not evaluate file content at the point of sharing or block external recipients. It suits detecting harassment, insider risk, and regulatory language breaches in communications.

  • ✗

    Microsoft Purview eDiscovery

    Why it's wrong here

    eDiscovery identifies and preserves content for legal investigations and holds; it does not inspect outbound sharing in real time or block it. It is the right choice for litigation, regulatory requests, and case review, not for preventing PII leaving to external recipients.

  • ✓

    Microsoft Purview Data Loss Prevention

    Why this is correct

    DLP policies inspect content for sensitive information types such as PII, then block sharing with external recipients and surface user notifications or policy tips. This directly satisfies both the prevention and notification requirements, unlike labels or retention, which govern classification and lifecycle rather than real-time sharing control.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.